Our Privacy Policy

Last updated: 1 October 2026

This Privacy Policy explains how SimSwift collects, uses, shares and stores your personal data when you use our website simswift.io and buy our prepaid travel eSIM data packages, and what rights you have. It applies together with our General Terms, our Terms of Use and our Cookie Policy.

1. Who we are (data controller).

The controller of your personal data is NORIX DEV EOOD, a single-member limited liability company (ЕООД) registered in Bulgaria, UIC/EIK 208920554, with its address at 1 Papunka Str., village of Grozdyovo, 9106, Dolni Chiflik Municipality, Varna Region, Bulgaria, trading as SimSwift (“SimSwift”, “we”, “us”).

Privacy contact: for any question or request about your personal data, email support@simswift.io (please write “Privacy” in the subject line) or call +359886360883 (Monday to Friday, 9:00–18:00 UK time).

2. Personal data we collect.

We collect only the data we need to run our website and deliver your eSIM:

  • Account data: your name, email address, phone number (if you provide it), your password (stored only in hashed form, never in plain text), your language and currency preferences, and your marketing-email preference.
  • Checkout and order data: first and last name, email address, phone number, billing address, the package you buy, order number, price, currency, any SimSwift points used, and order dates.
  • eSIM data: the eSIM identifiers and activation details (such as the ICCID and QR code) and the status, validity and data usage of your eSIM, which we receive from our eSIM provisioning partner.
  • Payment data: the payment method you chose, the payment status and the transaction reference returned by the payment provider. We do not store full card numbers or card security codes (CVV) – see section 5.
  • Consent records: your confirmations at checkout that you accept our terms, that you are at least 18 years old, and that you request immediate delivery of the eSIM and acknowledge that you lose your right of withdrawal once the eSIM is activated, together with the time, your IP address and your browser’s user agent.
  • Technical and security data: IP address, approximate country derived from your IP address (used to show prices in your local currency), browser and device type, and server and security logs that we use to protect the website against fraud, abuse and automated attacks.
  • Communications: messages you send us through the contact form or by email, and our replies.
  • Newsletter: your email address, if you subscribe to our newsletter.
  • Partner referral data: if you arrive through a partner’s referral link, the link identifier and the time, IP address and browser of the click.
  • Analytics data (only with your consent): information about how you use our website (pages visited, device and browser type, approximate location and interactions), collected through Google Analytics 4.

We do not ask for identity documents, and we do not collect biometric data or special categories of personal data. You can browse our website without an account, but we need the checkout data above to deliver an eSIM to you.

3. Where we get your data.

  • From you, when you create an account, place an order, contact us or subscribe to our newsletter.
  • Automatically from your device, when you use our website (see our Cookie Policy).
  • From our payment service providers (payment status and transaction reference) and from our eSIM provisioning partner (eSIM status and usage).

4. Why we use your data and our legal bases.

  • To create and manage your account – performance of a contract (Article 6(1)(b) GDPR).
  • To process your order and payment, deliver and support your eSIM, and send you order confirmations, receipts, invoices and service messages – performance of a contract (Article 6(1)(b) GDPR).
  • To answer your questions and complaints and to handle refund and withdrawal requests – performance of a contract and our obligations under consumer law (Article 6(1)(b) and (c) GDPR).
  • To keep accounting records and invoices and to comply with tax, consumer-protection and other legal obligations, including requests from competent authorities – legal obligation (Article 6(1)(c) GDPR).
  • To record the confirmations you give at checkout, so that we can prove them – legal obligation and our legitimate interest in establishing and defending legal claims (Article 6(1)(c) and (f) GDPR).
  • To prevent fraud and payment abuse, to authenticate card payments (3-D Secure) and to keep our website and systems secure – our legitimate interest in protecting our customers and our business (Article 6(1)(f) GDPR) and, where applicable, legal obligation.
  • To credit partners for purchases made through their referral links – our legitimate interest in running our partner programme (Article 6(1)(f) GDPR).
  • To show prices in your local currency based on your approximate location – our legitimate interest in offering a relevant website (Article 6(1)(f) GDPR).
  • To send you our newsletter and marketing emails – your consent (Article 6(1)(a) GDPR). You can withdraw it at any time with the unsubscribe link in every email or on your Profile page.
  • To measure how our website is used with Google Analytics – your consent (Article 6(1)(a) GDPR). You can withdraw it at any time in Cookie settings.
  • To establish, exercise or defend legal claims – our legitimate interest (Article 6(1)(f) GDPR).

Where we rely on legitimate interests, you have the right to object (see section 9). Providing the checkout data is necessary to conclude the contract; without it we cannot deliver an eSIM.

We do not make decisions that produce legal effects for you, or similarly significantly affect you, based solely on automated processing. Our automated security checks may block suspicious requests; if this affects you, contact us and a member of our team will review it.

5. Payments and card data.

Payments are processed by PCI DSS compliant payment service providers: FlowaPay (card payments), Paytech (hosted payment page, working with DSK Bank and PostBank) and PayPal. When you pay by card on our checkout, your card details are transmitted over an encrypted connection to the payment provider for authorisation and are not retained by SimSwift. When you pay through the Paytech payment page or PayPal, you enter your details directly on the provider’s page.

SimSwift never stores full card numbers or card security codes (CVV) in its systems. We keep only the payment status and the transaction reference needed to match the payment to your order, handle refunds and meet our accounting obligations.

3-D Secure: card payments are authenticated with 3-D Secure (Visa Secure / Mastercard Identity Check) where your card issuer supports it. The authentication takes place between you and your bank; we do not receive your online-banking credentials or one-time codes.

Payment providers also process your payment data under their own privacy policies, for example to meet their own legal obligations (PayPal: www.paypal.com/privacy).

6. Who we share your data with.

We share personal data only where necessary for the purposes above. We do not sell your personal data.

  • Payment service providers: FlowaPay, Paytech (and the banks it works with, DSK Bank and PostBank) and PayPal – to process payments, 3-D Secure authentication, refunds and chargebacks.
  • Our eSIM provisioning partner, Yesim – receives the order data needed to issue and manage your eSIM.
  • Our email delivery (SMTP) provider – to send order confirmations, receipts, invoices, service messages and, if you agreed, newsletters.
  • Hosting and infrastructure providers – to host our website, servers and databases.
  • Google (Google Analytics 4) – only if you consent to analytics cookies.
  • Partner brands and resellers – only if you bought through their referral link or partner page: they can see the order number, package, amount and date, and your name and email address, for referral attribution and commission calculation. They never receive your payment details.
  • Professional advisers (such as accountants, auditors and lawyers), who are bound by confidentiality.
  • Public authorities, courts and regulators (for example the National Revenue Agency, the Commission for Consumer Protection, the Commission for Personal Data Protection or law-enforcement authorities) – only when we are legally required to do so, or to establish, exercise or defend legal claims.
  • A buyer or successor, if our business or assets are sold or restructured, subject to this Policy.

Our service providers act on our instructions under data processing agreements, except where they act as independent controllers (for example payment providers and banks when meeting their own legal obligations).

7. International transfers.

Some of our service providers, such as Google and PayPal, may process personal data outside the European Economic Area (EEA), including in the United States. In that case we transfer data only where the European Commission has decided that the country ensures an adequate level of protection (including, for certified US companies, the EU-US Data Privacy Framework), or under the European Commission’s Standard Contractual Clauses, with additional safeguards where needed. You can ask for more information or a copy of the safeguards at support@simswift.io.

8. How long we keep your data.

  • Orders, invoices, payment records and the related checkout confirmations: up to 10 years, as required by the Bulgarian Accountancy Act and tax law.
  • Account data: for as long as your account is open. When you close your account, we delete or anonymise your account data, except data we must keep by law (such as invoices and order records).
  • Newsletter and marketing data: until you unsubscribe or withdraw your consent.
  • Contact-form and support messages: for as long as needed to handle your request and for up to 3 years afterwards, in case of follow-up questions or legal claims.
  • Security logs: for a limited period, normally no longer than 12 months, unless needed to investigate an incident.
  • Partner referral data: for as long as needed to calculate and pay partner commissions and, where linked to an order, as part of the order records above.
  • Cookies and analytics data: as listed in the table in section 10 and in our Cookie Policy.

9. Your rights.

Under the GDPR you have the right to:

  • access your personal data and receive a copy of it;
  • have inaccurate data corrected (rectification);
  • have your data erased, where there is no longer a legal reason to keep it;
  • restrict the processing of your data in certain cases;
  • receive the data you gave us in a structured, machine-readable format and have it transmitted to another controller (portability);
  • object to processing based on our legitimate interests, and object at any time to direct marketing;
  • withdraw any consent you have given at any time, without affecting the lawfulness of processing before the withdrawal.

How to exercise your rights: on the Profile page of your account you can edit your details, manage marketing emails, download a copy of your data and close your account. For any other request, email support@simswift.io. We reply within one month; for complex requests this can be extended by up to two further months, in which case we will tell you. Exercising your rights is free of charge. We may ask you to confirm your identity.

Right to complain: you can lodge a complaint with the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни, CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, cpdp.bg, kzld@cpdp.bg, or with the data protection authority of the EU country where you live or work. We would appreciate the chance to address your concern first.

10. Cookies.

We use strictly necessary cookies and browser storage to run the website, and analytics cookies only with your consent. We do not use advertising cookies. You can change your choice at any time with “Cookie settings” in the footer of every page. The table below summarises the cookies we use; full details are in our Cookie Policy.

NameCategoryExpiry
tokenStrictly necessaryUp to 7 days, or until you log out
brand_tokenStrictly necessary7 days, or until logout
reseller_tokenStrictly necessary7 days, or until logout
sw_brand_linkStrictly necessary120 days
cookie_consentStrictly necessary12 months
_gaAnalytics (only with consent)2 years
_ga_524TQRXPYBAnalytics (only with consent)2 years

11. Security.

We protect your data with appropriate technical and organisational measures, including encrypted connections (HTTPS/TLS), hashed passwords, access limited to staff and providers who need the data, and monitoring of our systems against abuse. No method of transmission or storage is completely secure. If a personal data breach is likely to put your rights at risk, we will notify the CPDP and, where required, you.

12. Age.

Our services are intended only for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe that a person under 18 has given us personal data, please contact support@simswift.io and we will delete it.

13. Changes to this Policy.

We may update this Policy from time to time. We publish the updated version on this page with a new “Last updated” date and, for material changes, inform registered users by email.